From e535392c52b30c487a0bd266229607746edaea1c Mon Sep 17 00:00:00 2001 From: Valentin PELUS Date: Sun, 28 Apr 2024 15:22:24 +0200 Subject: [PATCH 1/2] fix(charts): switch role and roleBinding to cluster scoped permissions --- .../templates/manager-permissions.yaml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml b/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml index 0aa4ce3..449862f 100644 --- a/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml +++ b/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml @@ -7,7 +7,7 @@ metadata: app.kubernetes.io/part-of: crik --- apiVersion: rbac.authorization.k8s.io/v1 -kind: Role +kind: ClusterRole metadata: name: crik-node-state-server labels: @@ -25,7 +25,7 @@ rules: - watch --- apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding +kind: ClusterRoleBinding metadata: name: crik-node-state-server labels: @@ -33,8 +33,9 @@ metadata: app.kubernetes.io/part-of: crik roleRef: apiGroup: rbac.authorization.k8s.io - kind: Role + kind: ClusterRole name: crik-node-state-server subjects: - kind: ServiceAccount name: crik-node-state-server + namespace: default From bfddb5d5217c52be9468ed2e87b3acfb0770f472 Mon Sep 17 00:00:00 2001 From: Valentin Pelus Date: Sun, 28 Apr 2024 19:15:04 +0200 Subject: [PATCH 2/2] Update cluster/charts/crik-node-state-server/templates/manager-permissions.yaml Co-authored-by: muvaffak --- .../crik-node-state-server/templates/manager-permissions.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml b/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml index 449862f..5719067 100644 --- a/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml +++ b/cluster/charts/crik-node-state-server/templates/manager-permissions.yaml @@ -38,4 +38,4 @@ roleRef: subjects: - kind: ServiceAccount name: crik-node-state-server - namespace: default + namespace: {{ .Release.Namespace }}